Unkey
Unkey is the developer platform for modern APIs, providing globally distributed API key management, rate limiting, identity management, analytics, and deployment capabilities. The platform enables API providers to issue, verify, and revoke keys with metadata, expiration, usage credits, permissions, and roles — without managing any infrastructure.
Solid contracts, transparent operations, and an easy start — typically complete on four or five facets with one clear soft spot.
API Evangelist profiles Unkey the way a machine reads it — 205 machine-readable artifacts across 8 APIs, pulled from the provider's own public surface and indexed so a developer, an analyst, or an AI agent can evaluate it against every other provider on the network.
Every provider in the network is reduced to the same set of machine-readable artifacts — OpenAPI contracts, event specifications, GraphQL schemas, runnable collections, pricing and rate-limit signals, security posture, OAuth scopes, and the agent surfaces (MCP servers and skills) that let software drive the API on its own. We profile them because the interface is the part of a company you can actually inspect: it is a truer signal of what a provider does than any marketing page. From those artifacts we compute the Kin Score — Unkey scores 60.9/100 (strong), with a separate agent-readiness read of 48/100 (agent ready). The full breakdown is below, followed by every artifact we hold — each card links through to its machine-readable definition on apis.io.
Kin Score
This is the API Evangelist rating — a single, repeatable read computed from the artifacts on this page. Green fill is points earned; the red track is points possible, so every bar shows earned-versus-possible at a glance.
How we profile Unkey
Each block below is one kind of artifact we hold for Unkey. For each we say what it is and why it earns a place in the profile, then list every one we've indexed — capped at two rows, scroll within the panel for the rest.
APIs 8
Each API is captured as its own OpenAPI definition — every operation, parameter, and response. This is the single most useful machine-readable description of what an API does, and it's what lets us score, lint, mock, and generate against it without asking the provider for anything.
Individual APIs this provider publishes, each with its own machine-readable definition.
Unkey analytics API
Analytics query operations
Unkey apis API
API management operations
Unkey deploy API
Deployment operations
Unkey identities API
Identity management operations
Unkey keys API
API key management operations
Unkey liveness API
Health check operations
Unkey permissions API
Permission and role management operations
Unkey ratelimit API
Rate limiting operations
Scroll within the panel for all 8 ·
Open Collections 1
Open, tool-agnostic collections carry the same runnable value as Postman without locking you to one client — the portable, forkable form of the same exercise.
Open, tool-agnostic API collections (OpenAPI-derived and Bruno).
Unkey API
OPEN COLLECTIONPricing Plans 1
Pricing is part of the interface. Machine-readable plans tell you what a tier costs and includes before you commit — one of the six things the Kin Score reads for commercial clarity.
Published pricing tiers and plan structures.
Unkey Plans Pricing
PLANSRate Limits 1
Rate limits are the difference between a demo that works and a production integration that doesn't fall over. Publishing them is an operational-transparency signal — and a hard requirement for any agent that plans its own throughput.
Documented rate limits and quota policies.
Unkey Rate Limits
RATE LIMITSFinOps 1
Cost, billing, and metering signals let a buyer model the financial operations of an API before it's live. We profile them for the same reason we profile pricing: the money is part of the contract.
Cost, billing, and metering signals for API financial operations.
Unkey Finops
FINOPSFeatures 16
The notable capabilities this provider advertises, captured as structured features so they can be searched and compared instead of read one landing page at a time.
Notable capabilities this provider offers.
Scroll within the panel for all 16 ·
Semantic Vocabularies 1
JSON-LD contexts give the data shared meaning across APIs. We profile them because semantics are what let a machine reconcile 'customer' here with 'customer' somewhere else.
JSON-LD contexts and semantic vocabularies used across these APIs.
Unkey Context
JSON-LDSpectral Rules 2
Governance rulesets we run against this provider's specs — the automated checks behind parts of the score. Profiling them makes the quality bar explicit and re-runnable, not a matter of opinion.
Unkey API Rules
SPECTRALUnkey API Rules
SPECTRALJSON Schema 149
Standalone JSON Schema definitions describe the data models behind the API. We profile them so the shapes are validatable on their own — useful long after a single request is forgotten.
Standalone JSON Schema definitions for this provider's data models.
BadRequestErrorDetails
JSON SCHEMABadRequestErrorResponse
JSON SCHEMABaseError
JSON SCHEMAConflictErrorResponse
JSON SCHEMAEmptyResponse
JSON SCHEMAForbiddenErrorResponse
JSON SCHEMAGoneErrorResponse
JSON SCHEMAUnkey Identity
JSON SCHEMAInternalServerErrorResponse
JSON SCHEMAUnkey API Key
JSON SCHEMAKeyCreditsData
JSON SCHEMAKeyCreditsRefill
JSON SCHEMAKeyResponseData
JSON SCHEMAKeysVerifyKeyCredits
JSON SCHEMAKeysVerifyKeyRatelimit
JSON SCHEMAMeta
JSON SCHEMANotFoundErrorResponse
JSON SCHEMAPagination
JSON SCHEMAPermission
JSON SCHEMAPreconditionFailedErrorResponse
JSON SCHEMAUnkey Rate Limit Result
JSON SCHEMARatelimitOverride
JSON SCHEMARatelimitRequest
JSON SCHEMARatelimitResponse
JSON SCHEMARole
JSON SCHEMAServiceUnavailableErrorResponse
JSON SCHEMATooManyRequestsErrorResponse
JSON SCHEMAUnauthorizedErrorResponse
JSON SCHEMAUnprocessableEntityErrorResponse
JSON SCHEMAUpdateKeyCreditsData
JSON SCHEMAUpdateKeyCreditsRefill
JSON SCHEMAV2AnalyticsGetVerificationsRequestBody
JSON SCHEMAV2AnalyticsGetVerificationsResponseBody
JSON SCHEMAV2AnalyticsGetVerificationsResponseData
JSON SCHEMAV2ApisCreateApiRequestBody
JSON SCHEMAV2ApisCreateApiResponseBody
JSON SCHEMAV2ApisCreateApiResponseData
JSON SCHEMAV2ApisDeleteApiRequestBody
JSON SCHEMAV2ApisDeleteApiResponseBody
JSON SCHEMAV2ApisGetApiRequestBody
JSON SCHEMAV2ApisGetApiResponseBody
JSON SCHEMAV2ApisGetApiResponseData
JSON SCHEMAV2ApisListKeysRequestBody
JSON SCHEMAV2ApisListKeysResponseBody
JSON SCHEMAV2ApisListKeysResponseData
JSON SCHEMAV2DeployCreateDeploymentRequestBody
JSON SCHEMAV2DeployCreateDeploymentResponseBody
JSON SCHEMAV2DeployCreateDeploymentResponseData
JSON SCHEMAV2DeployDeploymentStep
JSON SCHEMAV2DeployGetDeploymentRequestBody
JSON SCHEMAV2DeployGetDeploymentResponseBody
JSON SCHEMAV2DeployGetDeploymentResponseData
JSON SCHEMAV2DeployGitCommit
JSON SCHEMAV2IdentitiesCreateIdentityRequestBody
JSON SCHEMAV2IdentitiesCreateIdentityResponseBody
JSON SCHEMAV2IdentitiesCreateIdentityResponseData
JSON SCHEMAV2IdentitiesDeleteIdentityRequestBody
JSON SCHEMAV2IdentitiesDeleteIdentityResponseBody
JSON SCHEMAV2IdentitiesGetIdentityRequestBody
JSON SCHEMAV2IdentitiesGetIdentityResponseBody
JSON SCHEMAV2IdentitiesListIdentitiesRequestBody
JSON SCHEMAV2IdentitiesListIdentitiesResponseBody
JSON SCHEMAV2IdentitiesListIdentitiesResponseData
JSON SCHEMAV2IdentitiesUpdateIdentityRequestBody
JSON SCHEMAV2IdentitiesUpdateIdentityResponseBody
JSON SCHEMAV2KeysAddPermissionsRequestBody
JSON SCHEMAV2KeysAddPermissionsResponseBody
JSON SCHEMAV2KeysAddPermissionsResponseData
JSON SCHEMAV2KeysAddRolesRequestBody
JSON SCHEMAV2KeysAddRolesResponseBody
JSON SCHEMAV2KeysAddRolesResponseData
JSON SCHEMAV2KeysCreateKeyRequestBody
JSON SCHEMAV2KeysCreateKeyResponseBody
JSON SCHEMAV2KeysCreateKeyResponseData
JSON SCHEMAV2KeysDeleteKeyRequestBody
JSON SCHEMAV2KeysDeleteKeyResponseBody
JSON SCHEMAV2KeysGetKeyRequestBody
JSON SCHEMAV2KeysGetKeyResponseBody
JSON SCHEMAV2KeysMigrateKeyData
JSON SCHEMAV2KeysMigrateKeysMigration
JSON SCHEMAV2KeysMigrateKeysRequestBody
JSON SCHEMAV2KeysMigrateKeysResponseBody
JSON SCHEMAV2KeysMigrateKeysResponseData
JSON SCHEMAV2KeysRemovePermissionsRequestBody
JSON SCHEMAV2KeysRemovePermissionsResponseBody
JSON SCHEMAV2KeysRemovePermissionsResponseData
JSON SCHEMAV2KeysRemoveRolesRequestBody
JSON SCHEMAV2KeysRemoveRolesResponseBody
JSON SCHEMAV2KeysRemoveRolesResponseData
JSON SCHEMAV2KeysRerollKeyRequestBody
JSON SCHEMAV2KeysRerollKeyResponseBody
JSON SCHEMAV2KeysRerollKeyResponseData
JSON SCHEMAV2KeysSetPermissionsRequestBody
JSON SCHEMAV2KeysSetPermissionsResponseBody
JSON SCHEMAV2KeysSetPermissionsResponseData
JSON SCHEMAV2KeysSetRolesRequestBody
JSON SCHEMAV2KeysSetRolesResponseBody
JSON SCHEMAV2KeysSetRolesResponseData
JSON SCHEMAV2KeysUpdateCreditsRequestBody
JSON SCHEMAV2KeysUpdateCreditsResponseBody
JSON SCHEMAV2KeysUpdateKeyRequestBody
JSON SCHEMAV2KeysUpdateKeyResponseBody
JSON SCHEMAV2KeysVerifyKeyRequestBody
JSON SCHEMAV2KeysVerifyKeyResponseBody
JSON SCHEMAV2KeysVerifyKeyResponseData
JSON SCHEMAV2KeysWhoamiRequestBody
JSON SCHEMAV2KeysWhoamiResponseBody
JSON SCHEMAV2LivenessResponseBody
JSON SCHEMAV2LivenessResponseData
JSON SCHEMAV2PermissionsCreatePermissionRequestBody
JSON SCHEMAV2PermissionsCreatePermissionResponseBody
JSON SCHEMAV2PermissionsCreatePermissionResponseData
JSON SCHEMAV2PermissionsCreateRoleRequestBody
JSON SCHEMAV2PermissionsCreateRoleResponseBody
JSON SCHEMAV2PermissionsCreateRoleResponseData
JSON SCHEMAV2PermissionsDeletePermissionRequestBody
JSON SCHEMAV2PermissionsDeletePermissionResponseBody
JSON SCHEMAV2PermissionsDeleteRoleRequestBody
JSON SCHEMAV2PermissionsDeleteRoleResponseBody
JSON SCHEMAV2PermissionsGetPermissionRequestBody
JSON SCHEMAV2PermissionsGetPermissionResponseBody
JSON SCHEMAV2PermissionsGetRoleRequestBody
JSON SCHEMAV2PermissionsGetRoleResponseBody
JSON SCHEMAV2PermissionsListPermissionsRequestBody
JSON SCHEMAV2PermissionsListPermissionsResponseBody
JSON SCHEMAV2PermissionsListPermissionsResponseData
JSON SCHEMAV2PermissionsListRolesRequestBody
JSON SCHEMAV2PermissionsListRolesResponseBody
JSON SCHEMAV2PermissionsListRolesResponseData
JSON SCHEMAV2RatelimitDeleteOverrideRequestBody
JSON SCHEMAV2RatelimitDeleteOverrideResponseBody
JSON SCHEMAV2RatelimitDeleteOverrideResponseData
JSON SCHEMAV2RatelimitGetOverrideRequestBody
JSON SCHEMAV2RatelimitGetOverrideResponseBody
JSON SCHEMAV2RatelimitLimitRequestBody
JSON SCHEMAV2RatelimitLimitResponseBody
JSON SCHEMAV2RatelimitLimitResponseData
JSON SCHEMAV2RatelimitListOverridesRequestBody
JSON SCHEMAV2RatelimitListOverridesResponseBody
JSON SCHEMAV2RatelimitListOverridesResponseData
JSON SCHEMAV2RatelimitMultiLimitCheck
JSON SCHEMAV2RatelimitMultiLimitRequestBody
JSON SCHEMAV2RatelimitMultiLimitResponseBody
JSON SCHEMAV2RatelimitMultiLimitResponseData
JSON SCHEMAV2RatelimitSetOverrideRequestBody
JSON SCHEMAV2RatelimitSetOverrideResponseBody
JSON SCHEMAV2RatelimitSetOverrideResponseData
JSON SCHEMAValidationError
JSON SCHEMAVerifyKeyRatelimitData
JSON SCHEMAScroll within the panel for all 149 ·
JSON Structure 2
JSON Structure captures the data shapes in a form built for tooling — a complement to JSON Schema that keeps the model machine-legible.
JSON Structure definitions describing this provider's data shapes.
Unkey Key Structure
JSON STRUCTUREUnkey Structure
JSON STRUCTUREExamples 20
Real request and response payloads are what turn a spec from abstract into obvious — and they're one of the twelve things an agent needs to call an API correctly on the first try.
Example request and response payloads for these APIs.
Unkey Create Key Example
EXAMPLEUnkey Get Key Example
EXAMPLEUnkey Keysupdatekey Example
EXAMPLEUnkey Keysverifykey Example
EXAMPLEUnkey Liveness Example
EXAMPLEUnkey Ratelimitlimit Example
EXAMPLEUnkey Verify Key Example
EXAMPLEScroll within the panel for all 20 ·
Security Posture 2
Authentication, domain security, vulnerability disclosure, and trust-center signals — the evidence that a provider takes security seriously enough to document it. We profile it because you can't govern what you can't see.
Authentication, domain security, vulnerability disclosure, and trust-center signals.
Agentic Access 1
An x-agentic-access contract marks which operations are safe for an agent to run on its own and which need a human in the loop. It is the difference between an API an agent can use and one it can use safely.
Recommended x-agentic-access execution contracts for AI agents.
Resources
Every other property we hold for Unkey — documentation, portals, status pages, policies, and corporate surface — grouped by the job it does, following the integrator's arc from getting started to running in production.
Documentation 1
Reference material describing how the API behaves
Agent Surfaces 1
MCP servers, agent skills, and machine-readable catalogs
Design & Contract 2
Pagination, idempotency, versioning, errors, and events
Build 1
SDKs, sample code, and the tooling you integrate with
Access & Security 2
Authentication, authorization, and security posture
Operate 1
Status, limits, changes, and where to get help
Commercial 1
Pricing, plans, and the legal terms of use
Company 3
The organization behind the API
← All providers · Data indexed from github.com/api-evangelist/unkey · machine-readable index on apis.io